Explanation
Threat actors are using a Chronopost theme to collect personal information and credit card credentials.
The phishing mail leads the user to believe that the delivery of a parcel was interrupted because it did not respect the indicated weight.
When clicking on the button “MON-COLIS”, the user is first presented a fake Chronopost website showing a fake delivery notice.
On this page, the user has to click on “+ FORMULAIRE COLIS”, after which they have to enter personal information, such as name, surname, address and date of birth.
Once they have provided this information, they are redirected to another fake form. The goal is to collect credit card credentials.
Example